# IP Intelligence Briefing: 46.224.128.127/32
Classification: Moderate Risk (Risk Score: 40/100)
Date: 2026-06-20
Assigned Analyst: SOC Intelligence Team
## Executive Summary
IP 46.224.128.127 is a Hetzner-hosted cloud compute endpoint located in Falkenstein, Saxony, Germany. While the IP itself shows no direct threat indicators, it resolves to the domain vnc.sofortonline.at (VNC service) and is associated with multiple DNSBL listings (2/8). The infrastructure shows moderate risk due to route instability and minimal reputation signals. No immediate blocking recommended; continue monitoring for behavioral anomalies.
## Infrastructure Profile
| Attribute | Value |
|---|---|
| **IP Address** | 46.224.128.127/32 |
| **ASN** | 24940 (Hetzner Online GmbH) |
| **Provider** | Hetzner - Cloud Compute |
| **Country** | DE (Saxony, Falkenstein) |
| **BGP Prefix** | 46.224.0.0/15 |
| **Route Stability** | Unstable (false) |
| **DNSSEC** | Valid |
## Service Fingerprint
- HTTP Server: nginx/1.24.0 (Ubuntu)
- Open Ports: 80/tcp (HTTP), 443/tcp (HTTPS), 22/tcp (SSH)
- TLS Certificate: CN=vnc.sofortonline.at (Let's Encrypt)
- PTR Hostname: static.127.128.224.46.clients.your-server.de
- DNS Reputation: Forward resolution confirmed
## Threat Assessment
Current Risk Score: 40/100 (Moderate)
Threat Indicators:
- No active threat indicators detected
- Not identified as Tor exit node
- Not classified as known attacker or spam source
- Blacklist count: 0 (direct threats)
- DNSBL listings: 2 of 8 total lists (reputation concern)
DNSBL Analysis: The IP appears on 2 DNSBL entries, suggesting prior association with spam or malicious activity. This warrants awareness but does not constitute immediate evidence of current compromise.
## Neighborhood Analysis
Subnet: 46.224.128.127/24
Abuse Density: 1 (Low)
Classification: Mostly clean
Sibling IPs: 1 active, 1 threat-identified
The subnet shows minimal abuse activity overall, indicating this endpoint's risk is primarily derived from individual reputation factors rather than neighborhood contamination.
## Historical Observations
Total Observations: 24
Observation Window: 2026-06-15 to 2026-06-20
Key temporal signals:
- DNS records resolved to both `sofortonline.at` and `your-server.de`
- HTTP response code 301 (redirect) with nginx server identification
- SPF record: `v=spf1 include:spf.easyname.com -all` (sofortonline.at)
- DMARC policy: `p=none;sp=none;adkim=r;aspf=r` (your-server.de)
The IP demonstrates persistent association with legitimate hosting infrastructure domains. No escalation in threat posture observed.
## Related Entities
DNS Associations:
- static.127.128.224.46.clients.your-server.de (repeated)
Network Associations:
- CLOUD-FSN1 (Hetzner data center network)
Campaign Correlation: None detected
## Recommended Actions
Firewall Rules (for reference):
```
iptables -A INPUT -s 46.224.128.127 -j DROP
nft add rule inet filter input ip saddr 46.224.128.127 drop
```
Policy Recommendation: No immediate blocking action required. The IP is hosted on a legitimate German cloud provider and shows association with legitimate business domains. The DNSBL listings and route instability suggest the need for continued monitoring rather than defensive blocking.
Monitoring Parameters:
- Track for changes in DNS resolution patterns
- Monitor for new threat indicator associations
- Watch for changes in TLS certificate subjects
- Observe for lateral connections to known malicious infrastructure
## Conclusion
IP 46.224.128.127 represents a low-to-moderate risk endpoint on Hetzner cloud infrastructure. While the moderate risk score (40) and DNSBL listings warrant awareness, the absence of active threat indicators and association with legitimate hosting domains suggest this is not an immediate threat. Recommend maintaining passive monitoring and avoiding reactive blocking without additional corroborating evidence.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Hetzner Online GmbH - Contact Role |
| ASN | AS24940 |
| Network Name | โ |
| CIDR Block | โ |
| RIR | RIPE |
| Country | โ |
| Abuse Contact | Available via RDAP |
๐ DNS Intelligence
| PTR | static.127.128.224.46.clients.your-server.de |
| Forward Confirmed | Yes โ FCrDNS verified |
| Forward Hostnames | static.127.128.224.46.clients.your-server.de |
๐ DNS Hygiene
| Hygiene Score | 100% (Excellent) |
| SPF | 2/2 domains |
| DMARC | 1/2 domains |
| FCrDNS | Verified |
| DNSSEC | Valid |
| CAA | Present |
| Domains Checked | 2 domains |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Web Server |
| Network Tier | Hosting โ Infrastructure provider without advanced routing |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| 80 | http | tcp | โ |
| 443 | https | tcp | โ |
| 22 | ssh | tcp | |
| Closed Ports | 25, 3389, 8080, 8443 (3 open / 7 scanned) | ||
| Server | nginx/1.24.0 (Ubuntu) |
| HTTP Title | โ |
| SSH Version | SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.16 |
๐ TLS Certificate
| SANs | vnc.sofortonline.at |
| Valid From | 2026-05-29T07:07:54+00:00 |
| Valid Until | 2026-08-27T07:07:53+00:00 |
| TLS Protocol | Tls13 |
| Cipher Suite | TLS_AES_256_GCM_SHA384 |
| Signature Algorithm | sha384ECDSA |
| Validity Period | 89 days |
| Serial Number | 064BDA67B7A2410B6072329F3A46013213DF |
| Thumbprint | 80961DCF9695C99FF5C550CA45AFA2B0380C7BEB |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 22% | 2 | 4 |
| routing | 13% | 1 | 1 |
| services | 30% | 2 | 3 |
| ownership | 24% | 2 | 3 |
| reputation | 26% | 1 | 3 |
| geolocation | 39% | 2 | 3 |
| Overall | 26% | 10 | 17 |
| Data Coherence | Consistent (100%) |
| Attribution | Moderate (70%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-18 03:23:15 UTC |
| Last Seen | 2026-06-28 06:29:44 UTC |
| Profile Built | 2026-06-29 00:35:04 UTC |
| Data Freshness | Live |
| Signal Types | 23 |
| Total Observations | 27 |
Full dossier details are available via our API.